
CVE-2024-50483
Meetup <= 0.1 - Authentication Bypass via Account Takeover

Meetup <= 0.1 - Authentication Bypass via Account Takeover

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

CVE-2020-13654 - XWiki Platform < 12.8 - Stored XSS → CSRF → Account Takeover

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

Online Discussion Forum Site 1.0 - Account Takeover

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

【Teedy 1.11】Account Takeover via XSS

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover